Security
SS Recruit is moving into production MVP with a focus on authentication, organization resolution, RLS, candidate events and secure server-side AI.
Trust stack
The product is being hardened around tenant boundaries, role permissions, auditable candidate activity and server-side AI execution.
User identity and role resolution
Every record belongs to the right tenant
RLS protects candidates, notes and events
Candidate events create accountability
Tenant-aware services and database policies keep customer data scoped by organization.
CEO, Admin, Recruiter, Client and Affiliate permissions are modeled around real workflows.
Supabase/Postgres policies are being hardened around profiles, organizations and candidate records.
Candidate events track important actions such as created, updated, CV uploaded and interview scheduled.
AI provider keys stay server-side only and Copilot outputs are cached with cost/run metadata.
The roadmap now prioritizes trust, persistence, lifecycle events and multi-tenant correctness.
Ready for serious recruiting operations
Show clients a product that manages intake, calls, scheduling, source intelligence and candidate visibility from one workspace.